Description
This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
Published: 2025-03-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

This vulnerability allows an application to read a user’s Safari bookmarks without performing the required entitlement verification. The missing entitlement check gives the app unauthorized access to potentially sensitive bookmark information, compromising user confidentiality. The flaw represents a Missing Authorization weakness, as defined by CWE‑862.

Affected Systems

Apple iPadOS and Apple macOS are affected. On iPadOS, the vulnerability exists in all releases prior to iPadOS 17.7.7. On macOS, the flaw is present on Sequoia, Sonoma, and Ventura versions older than macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5 respectively.

Risk and Exploitability

With a CVSS score of 9.8, the vulnerability is rated critical. The EPSS score is less than 1 %, indicating that, as of the current data, the likelihood of exploitation is low. The flaw resides in a local attack vector whereby a malicious application on the device can access Safari bookmarks. Though not listed in the CISA KEV catalog, its high severity warrants prompt patching.

Generated by OpenCVE AI on April 28, 2026 at 02:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all devices to iPadOS 17.7.7 or later, macOS Sequoia 15.4 or later, macOS Sonoma 14.7.5 or later, or macOS Ventura 13.7.5 or later to apply the entitlement fix.
  • Review installed applications and remove any that request Safari bookmark access for no legitimate reason.
  • In managed environments, enforce app sandbox restrictions so that unapproved applications cannot read Safari bookmarks until the OS update is installed.

Generated by OpenCVE AI on April 28, 2026 at 02:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8953 This issue was addressed with additional entitlement checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
History

Tue, 28 Apr 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Safari Bookmark Access via Missing Entitlement Check

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check. This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
References

Mon, 03 Nov 2025 22:30:00 +0000


Mon, 03 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 01 Apr 2025 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:23:06.419Z

Reserved: 2025-01-17T00:00:45.015Z

Link: CVE-2025-24259

cve-icon Vulnrichment

Updated: 2025-11-03T21:11:26.167Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:22.820

Modified: 2026-04-02T19:19:29.113

Link: CVE-2025-24259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T02:45:11Z

Weaknesses